nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36998 CVE-2020-36998
MEDIUM
forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
Record summary
CVE-2020-36998 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
E-Learning SuiteBrowse forma / E-Learning Suite | CVE List | Through 2.3.0.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBforma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site ScriptingExploitDB exploitby Daniel OrtizNot analyzed1 file
References
5Vendor Homepageproduct
https://sourceforge.net/projects/forma Software Download Linkproduct
https://sourceforge.net/projects/forma/files/latest/download ExploitDB-48478exploit
https://www.exploit-db.com/exploits/48478 VulnCheck Advisory: forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site ScriptingThird-party advisory
https://www.vulncheck.com/advisories/formalms-the-e-learning-suite-persistent-cross-site-scripting